Currentfold

Privacy

Currentfold is a reader. It needs an address to identify your account and a record of what you follow and what you have read, and it needs nothing else. This page says exactly what that means, in the order you would ask.

Who operates Currentfold

Currentfold is operated by Tommy Riska in Norway. There is no company. For this policy, and for the data held for your account, write to accounts@currentfold.com. For help using the reader, see support.

What Currentfold does not do

  • No analytics or product telemetry, in the reader or on this site.
  • No advertising, ad networks, or tracking pixels.
  • No third-party scripts, tag managers, or fonts loaded from elsewhere.
  • No selling, renting or sharing of your data.
  • No profiling of your reading, and no recommendation model built from it.

This page is a static document. It sets no cookies and makes no requests to any other domain, which is why it has no consent banner.

What the reader stores

Your account

An email address, and either a password (stored only as a hash) or a link to your Google account, depending on how you signed in. If you connect Google, Currentfold keeps the stable identifier Google issues and the verified address, not your Google password.

Sign in with Apple is coming on iOS. It is not a sign-in option on the web. When it is available, Currentfold will keep the stable identifier Apple issues. If you share your email, Currentfold keeps that verified address. If you hide it, Apple’s private relay forwards Currentfold account mail to you; Currentfold sees the relay address, not the real one.

Your reading

Your subscriptions and folders; the articles those feeds deliver; which of them you have read, starred, or put in Read later; the links you saved and the readable copies fetched for them; your highlights and their notes; your labels, rules and notification records; your reading positions and audio positions; and your preferences. This is what the product is: without it there is nothing to show you.

Signing in

A session cookie so the browser stays signed in, and one record per signed-in browser or device so you can end a session from Settings → Account. Native apps hold a rotating credential in the device keychain instead. App passwords you create for Google Reader-compatible clients are stored so they can be checked and revoked.

On your device

Reading preferences that are device-specific — text size, body font, column width, theme — live in your browser’s local storage, not on the server. If you download articles for offline reading, those copies are stored on that device and cleared when you delete the account or restore a backup.

Technical records

The server keeps ordinary request logs, and its rate limits count failed sign-in attempts against a hashed form of the address and the network they came from. These exist to keep the service working and to make password guessing expensive.

Currentfold keeps account and reading data to run the reader you asked for. Request logs and rate-limit records exist to keep the service secure.

Who else is involved

  • Cloudflare sits in front of Currentfold as its network edge. Requests to this site and to the reader pass through Cloudflare, which keeps its own connection logs and applies its security filtering. Currentfold reads the aggregate traffic statistics Cloudflare derives at that edge — counts of requests and approximate visitors, never who you are — and that is the only measurement there is: nothing is added to any page to watch you.
  • Resend delivers account email. Messages are sent from accounts@send.currentfold.com, and Resend processes the recipient address and message content to deliver them.
  • Google is involved only if you choose to sign in with Google, and only for that sign-in.
  • Apple is involved if you use Sign in with Apple on iOS when that is available, and only for that sign-in. Apple also delivers push notifications to Apple devices you switch them on for (APNs).
  • Your browser’s push service — Apple, Google or Mozilla, depending on the browser — carries push notifications, and only for the devices you switch them on for. The notification content is encrypted to that device.

That is the complete list. No analytics provider, no advertising network, no data broker, no session recorder.

Cloudflare, Resend, Google and Apple are not in Norway. When they process data so Currentfold can run, it may be processed outside the EEA under those providers’ own terms. Currentfold does not sell them your data; they see what they need to provide their service.

Email

Currentfold emails you when you asked it to or when your account needs it: verifying an address, confirming a change of address, recovering a password, an invitation you were sent, and the daily or weekly digest you scheduled yourself. Digests carry a one-click unsubscribe and can be turned off in Settings → Notifications. There is no marketing email. If you used Sign in with Apple Hide My Email, those messages go through Apple’s relay.

Fetching on your behalf

Currentfold’s server fetches your feeds and the pages you save — your browser does not. A publisher therefore sees a request from Currentfold identifying itself as Currentfold/<version>, not a request from you. Currentfold does not tell any publisher who subscribes to them.

How long it is kept

Your account data is kept until you delete it. Deleting your account removes it in one transaction; the shared article records that other accounts also subscribe to remain, without any connection to you. Server backups hold a copy for 14 days, so a short window can pass before the last copy of deleted data is gone.

Taking it with you, and deleting it

Settings → Subscriptions & data downloads a complete JSON backup of your account’s reader data — preferences, subscriptions, articles, reading state, saved pages, labels, rules, highlights and your digest schedule — and exports your subscriptions as OPML. Neither contains password hashes or anyone else’s data.

Settings → Account deletes the account. It asks for your email address, the word DELETE, and your password, and then removes your reader data and any connected provider identities. You do not need to ask anyone, and nothing waits on us. Deletion is also in Settings in the iOS app when it is used; the same account is removed.

If you are the owner of this deployment, transfer ownership first — that owner account cannot be deleted while it still owns the instance.

Your rights

You can ask for a copy of the data, a correction, or deletion, and you can take it with you as above. Write to accounts@currentfold.com. If you are in the EEA or the UK you can also complain to your data protection authority; in Norway that is Datatilsynet.

Contact

Questions about this policy, or about the data held for your account: accounts@currentfold.com. For help using the reader, see support. Using Currentfold is also covered by the terms.

Changes

If this policy changes in a way that affects what is collected or who it is shared with, the date at the top changes and the change is spelled out, not slipped in.